Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

1, 5, 395, 0 4.00%
1, 5, 395, 0 4.00%
1, 5, 393, 22 36.00%
1, 5, 393, 22 12.00%
1, 5, 393, 18 20.00%
1, 5, 393, 18 4.00%
1, 5, 388, 0 12.00%
1, 5, 388, 0 4.00%
1, 5, 350, 0 4.00%

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
LookupAccountNameW, RegCloseKey, RegQueryValueExW, SetServiceStatus, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, InitializeSecurityDescriptor, InitializeAcl, GetAce, AdjustTokenPrivileges, OpenProcessToken, MakeAbsoluteSD, OpenThreadToken, RegCreateKeyExW, RegOpenKeyExW, SetSecurityDescriptorOwner, SetKernelObjectSecurity, SetSecurityDescriptorGroup, GetSecurityInfo, AddAce, AllocateAndInitializeSid, LookupPrivilegeValueW, CreateProcessAsUserW, EqualSid, ConvertStringSidToSidW, SetThreadToken, DuplicateTokenEx, CreateRestrictedToken, SetSecurityInfo, GetSecurityDescriptorSacl, SetTokenInformation, GetTokenInformation, SetSecurityDescriptorSacl, SetSecurityDescriptorDacl, AddAuditAccessAce, AddAccessAllowedAce, RegDeleteValueW, RegEnumValueW, RegOpenKeyW, RegCreateKeyW, ImpersonateNamedPipeClient, RevertToSelf, ImpersonateLoggedOnUser, ConvertSidToStringSidW, RegSetValueExW
crypt32.dll
CertGetIssuerCertificateFromStore, CertFindCertificateInStore, CertCreateCertificateChainEngine, CertGetCertificateChain, CryptQueryObject, CryptHashPublicKeyInfo, CertGetNameStringW, CertNameToStrW, CertGetCertificateContextProperty, CryptDecodeObject, CryptMsgClose, CertFreeCertificateChainEngine, CertFreeCertificateChain, CertCloseStore, CertOpenSystemStoreW, CryptMsgGetParam, CertFreeCertificateContext, CertEnumCertificatesInStore
kernel32.dll
SetLastError, WaitForSingleObject, GetTickCount, GetThreadPriority, FreeLibrary, GetCurrentThread, SetThreadPriority, CreateEventW, CloseHandle, CreateToolhelp32Snapshot, Process32FirstW, SetUnhandledExceptionFilter, SetEvent, InterlockedCompareExchange, Process32NextW, QueueUserAPC, DeviceIoControl, SleepEx, GetVersion, TerminateProcess, OpenThread, DuplicateHandle, GetModuleHandleW, InterlockedExchange, CreateProcessW, GetExitCodeProcess, LocalFree, ResumeThread, GetStartupInfoA, UnhandledExceptionFilter, OpenProcess, QueryPerformanceCounter, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, GetCurrentProcess, SetProcessWorkingSetSize, Sleep, GetProcAddress, LoadLibraryW, GetLastError, WaitForMultipleObjects, ResetEvent, GetComputerNameW, QueueUserWorkItem, CreateFileMappingW, MapViewOfFile, UnmapViewOfFile, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, GetEnvironmentStringsW, SetEnvironmentVariableW, GetWindowsDirectoryW, GetTempPathW, CreateDirectoryW, GetEnvironmentVariableW, GetFileAttributesW, MultiByteToWideChar, FindFirstFileW, GetModuleFileNameW, FindClose, SearchPathW, WriteFile, FlushFileBuffers, DisconnectNamedPipe, ReadFile, ConnectNamedPipe, CreateNamedPipeW, TlsAlloc, GetCurrentDirectoryW, TlsFree, OpenFileMappingW, VirtualQuery, lstrcmpA, IsBadReadPtr, IsBadWritePtr, lstrcpynW, VerLanguageNameW, FormatMessageW, HeapDestroy, HeapCreate, GetFileSizeEx, MoveFileExW, SetFilePointerEx, CompareFileTime, HeapFree, GetCommandLineW, ExitThread, GetLocalTime, ReleaseMutex, CreateMutexW, WaitForSingleObjectEx, SetEndOfFile, HeapAlloc, GetSystemTime, CompareStringA, CompareStringW, GetShortPathNameW, WaitNamedPipeW, GetPrivateProfileIntW, GetPrivateProfileStringW, GetVersionExW, WideCharToMultiByte, RemoveDirectoryW, SetFileAttributesW, FindNextFileW, DeleteFileW, OutputDebugStringW, ReadProcessMemory, GetExitCodeThread, CreateThread, GetFileSize, CreateFileW, CopyFileW, TlsGetValue, TlsSetValue, GetProcessAffinityMask, InterlockedIncrement, InterlockedDecrement, VirtualAlloc, VirtualFree, QueryPerformanceFrequency, IsDebuggerPresent, GetSystemDirectoryW, GetLongPathNameW, SystemTimeToFileTime
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ntdll.dll
ZwDelayExecution, ZwSetInformationFile, ZwQueryFullAttributesFile, ZwWaitForMultipleObjects, ZwOpenKey, RtlFreeUnicodeString, ZwCreateFile, ZwQueryInformationFile, ZwOpenThread, RtlGetVersion, ZwFlushBuffersFile, ZwWriteFile, ZwReadFile, ZwReleaseMutant, RtlFormatCurrentUserKeyPath, ZwCreateKey, RtlInitUnicodeString, ZwAllocateVirtualMemory, ZwWriteVirtualMemory, ZwFlushInstructionCache, ZwQueryInformationProcess, ZwQueryKey, ZwYieldExecution, ZwCreateEvent, ZwWaitForSingleObject, ZwResetEvent, ZwSetValueKey, ZwQueryInformationThread, ZwOpenDirectoryObject, ZwOpenSymbolicLinkObject, ZwQuerySymbolicLinkObject, ZwOpenSection, ZwMapViewOfSection, ZwReadVirtualMemory, ZwQueryVirtualMemory, ZwQueryValueKey, ZwProtectVirtualMemory, ZwSetEvent, ZwAreMappedFilesTheSame, ZwUnmapViewOfSection, RtlNtStatusToDosError, ZwOpenMutant, ZwClose, ZwCreateMutant, ZwOpenFile, ZwOpenEvent
ole32.dll
CoInitialize, CoUninitialize
psapi.dll
EnumProcesses
shell32.dll
CommandLineToArgvW, SHGetSpecialFolderPathW
shlwapi.dll
SHDeleteKeyW
user32.dll
CharLowerW, wsprintfW, CharUpperW, OpenInputDesktop, SetThreadDesktop, GetThreadDesktop, OpenDesktopW, CloseDesktop, GetDesktopWindow, FindWindowExW, GetUserObjectInformationW, CharUpperBuffW, CharUpperBuffA, CharLowerBuffA, RegisterWindowMessageW, MessageBoxW, PeekMessageW, MsgWaitForMultipleObjects, DispatchMessageW, TranslateMessage, CharLowerBuffW
userenv.dll
DestroyEnvironmentBlock, CreateEnvironmentBlock
version.dll
VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
wintrust.dll
WinVerifyTrust, WTHelperGetProvSignerFromChain, CryptCATAdminReleaseContext, CryptCATAdminReleaseCatalogContext, CryptCATAdminEnumCatalogFromHash, CryptCATCatalogInfoFromContext, CryptCATAdminAcquireContext, WTHelperProvDataFromStateData, CryptCATAdminCalcHashFromFileHandle

iswsvc.exe

ZoneAlarm Browser Security by Check Point Software Technologies Ltd. (Signed)

Remove iswsvc.exe
Version:   1, 5, 393, 22
MD5:   d9a4c1353cc653f8e2fe4d2c6a490e96
SHA1:   5e160a60e9c2b015f8215b8d181361d4968c3d42
SHA256:   c77d09df7f877ef14a67352255fac7423ed970c8c66c2029fba2c7d789a8fbe1

What is iswsvc.exe?

Check Point's ZoneAlarm ForceField is designed to secure Web browsing sessions through the use of browser virtualization, inline download scanning and DNS validation services.

About iswsvc.exe (from Check Point Software Technologies Ltd.)

Get ZoneAlarm ForceField for your browser. ForceField works hard at Web safety so you don't have to, but you should continue to browse with common sense in mind.

Overview

iswsvc.exe runs as a service under the name ZoneAlarm Toolbar IswSvc (IswSvc) with extensive SYSTEM privileges (full administrator access). This is typically installed with the program Audio 180% published by Franzis Verlag Gmbh. The file is digitally signed by Check Point Software Technologies Ltd. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:iswsvc.exe
Publisher:Check Point Software Technologies
Product name:ZoneAlarm Browser Security
Typical file path:C:\Program Files\checkpoint\zaforcefield\iswsvc.exe
File version:1, 5, 393, 22
Size:808.66 KB (828,072 bytes)
Certificate
Issued to:Check Point Software Technologies Ltd.
Authority (CA):VeriSign
Expiration date:Monday, May 5, 2014
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Franzis Verlag Gmbh
9% remove
The full version of "Audio 180%" under tidier interface offers a total of ten tools to help you around all common tasks get the job done with audio and sound. using the audio player you give songs and playlists back, audio streamer allows you to receive and record streams from the Internet. With the audio CD / DVD Ripper copy audio files from CDs and DVDs. Additionally, you can burn audio CDs, edit MP3, WAV and OGG files, and convert tr...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'IswSvc' (ZoneAlarm Toolbar IswSvc)
  • IswSvc

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00083694%
0.028634%
Kernel CPU:0.00019545%
0.013761%
User CPU:0.00064149%
0.014873%
Kernel CPU time:2,957 ms/min
100,923,805ms/min
CPU cycles:331,470/sec
17,470,203/sec
Memory
Private memory:7.51 MB
21.59 MB
Private (maximum):9.74 MB
Private (minimum):5.19 MB
Non-paged memory:7.51 MB
21.59 MB
Virtual memory:107.42 MB
140.96 MB
Virtual memory (peak):207.98 MB
169.69 MB
Working set:8.34 MB
18.61 MB
Working set (peak):45.34 MB
37.95 MB
Page faults:183,516/min
2,039/min
I/O
I/O read transfer:10 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:544 Bytes/sec
274.99 KB/min
I/O write operations:3/sec
227/min
I/O other transfer:1.17 KB/sec
448.09 KB/min
I/O other operations:127/sec
1,671/min
Resource allocations
Threads:12
12
Handles:278
600

BehaviorsProcess properties

Integrety level:Undefined
Platform:64-bit
Command line:"C:\Program Files\checkpoint\zaforcefield\iswsvc.exe"
Owner:SYSTEM
Windows Service
Service name:IswSvc
Display name:ZoneAlarm Toolbar IswSvc
Type:Win32OwnProcess
Parent process:services.exe (by Microsoft)

ResourcesThreads

Averages
 
ntdll.dll
Total CPU:0.00135491%
0.272967%
Kernel CPU:0.00079554%
0.107585%
User CPU:0.00055937%
0.165382%
CPU cycles:40,503/sec
5,741,424/sec
Memory:1.75 MB
1.16 MB
MSVCR80.dll
Total CPU:0.00009552%
Kernel CPU:0.00003821%
User CPU:0.00005731%
CPU cycles:2,662/sec
Memory:804 KB
IswSvc.exe (main module)
Total CPU:0.00003820%
Kernel CPU:0.00003820%
User CPU:0.00000000%
CPU cycles:539/sec
Memory:820 KB
sechost.dll (Host for SCM/SDDL/LSA Lookup APIs by Microsoft)
Total CPU:0.00001910%
Kernel CPU:0.00001910%
User CPU:0.00000000%
CPU cycles:638/sec
Memory:124 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 48.00%
Microsoft Windows XP 16.00%
Windows Vista Home Basic 8.00%
Windows 8 Pro 8.00%
Windows 7 Professional 8.00%
Windows 7 Ultimate N 4.00%
Windows Vista Ultimate 4.00%
Windows 7 Ultimate 4.00%

Distribution by countryDistribution by country

United States installs about 60.00% of ZoneAlarm Browser Security.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 80.00%
Acer 20.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE